Microsoft Foundry
Connect Claude Code to Claude deployments in Microsoft Foundry on Azure, with API key, Entra ID or bearer token auth, pinned deployments and RBAC.
Microsoft Foundry is the route for organisations standardised on Azure. You create Claude deployments in a Foundry resource, Claude Code talks to that resource, and the spend lands in Azure Cost Management with access governed by Azure RBAC. I have set this up for a couple of Microsoft-heavy clients, and the main thing to remember is that there is no setup wizard and no safety net on models: you configure everything through environment variables and you must pin deployments.
Like the other cloud providers, Foundry does not give you the claude.ai-only features. Check feature availability before committing.
Before you start
- An Azure subscription with access to Microsoft Foundry.
- RBAC rights to create Foundry resources and deployments.
- The Azure CLI, if you plan to sign in with Entra ID from a workstation.
Step 1: create the resource and deployments
- In the Microsoft Foundry portal, create a resource and note its name.
- Create a deployment for each Claude model family you want (Opus, Sonnet, Haiku), noting each deployment name. You will use those names as the model variables later.
- While configuring each deployment, choose its hosting option, which decides whether inference runs on Azure or on Anthropic's infrastructure. Pick a specific model version, not "auto-update to latest".
Step 2: choose how to authenticate
| Method | Set | When to use it |
|---|---|---|
| API key | ANTHROPIC_FOUNDRY_API_KEY | Quick starts, or where Entra ID is not practical. Copy it from Endpoints and keys on the resource. |
| Microsoft Entra ID | Nothing; leave both Foundry credential variables unset | Most teams. Claude Code uses the Azure SDK default credential chain (an az login session locally, managed identity in Azure). No key to store. |
| Bearer token | ANTHROPIC_FOUNDRY_AUTH_TOKEN | Another process has already fetched an Entra ID access token for the resource (v2.1.203+) |
For Entra ID on a laptop:
az login
The bearer token is sent as Authorization: Bearer on every request and beats both the API key and the credential chain. /logout does nothing on Foundry, because Azure credentials handle authentication.
Step 3: point Claude Code at Foundry
export CLAUDE_CODE_USE_FOUNDRY=1
export ANTHROPIC_FOUNDRY_RESOURCE=contoso-claude-uks
# or give the whole URL instead:
# export ANTHROPIC_FOUNDRY_BASE_URL=https://contoso-claude-uks.services.ai.azure.com/anthropic
ANTHROPIC_FOUNDRY_RESOURCE must be the bare resource name. A URL or host name there is rejected when you send your first message.
Step 4: pin your deployments
Warning: Always pin on Foundry. Unpinned aliases resolve to Claude Code's built-in Foundry defaults, which may not exist in your resource, and there is no startup check or fallback: requests simply fail.
Set each variable to the deployment name you created:
export ANTHROPIC_DEFAULT_OPUS_MODEL='claude-opus-4-8'
export ANTHROPIC_DEFAULT_SONNET_MODEL='claude-sonnet-5'
export ANTHROPIC_DEFAULT_HAIKU_MODEL='claude-haiku-4-5'
Without the Opus variable, opus resolves to Opus 4.6 on Foundry, so pinning a newer Opus is worth doing.
Background tasks like session titles normally use a Haiku-class model. On Foundry they default to the primary model, because not every resource has a Haiku deployment. Set ANTHROPIC_DEFAULT_HAIKU_MODEL to a Haiku deployment you do have and background work becomes noticeably cheaper.
Prompt caching is on automatically. ENABLE_PROMPT_CACHING_1H=1 requests a one-hour TTL instead of five minutes, with cache writes billed higher. See model configuration for the full list of model variables.
Step 5: run and check
claude
Claude Code reads the Foundry variables from the environment and connects on the first prompt. Run /status: the API provider line should say Microsoft Foundry along with your resource name or base URL.
For a team, I put the non-secret variables in a shared settings file and let Entra ID handle identity:
{
"env": {
"CLAUDE_CODE_USE_FOUNDRY": "1",
"ANTHROPIC_FOUNDRY_RESOURCE": "contoso-claude-uks",
"ANTHROPIC_DEFAULT_OPUS_MODEL": "claude-opus-4-8",
"ANTHROPIC_DEFAULT_SONNET_MODEL": "claude-sonnet-5",
"ANTHROPIC_DEFAULT_HAIKU_MODEL": "claude-haiku-4-5"
}
}
Deployed through managed settings, that gives every developer the same provider and models without them touching a shell profile.
Azure RBAC
The built-in Azure AI User and Cognitive Services User roles both include everything needed to call Claude models. For a tighter custom role, grant this data action:
{
"permissions": [
{
"dataActions": ["Microsoft.CognitiveServices/accounts/providers/*"]
}
]
}
Troubleshooting
| Error | Fix |
|---|---|
Failed to get token from azureADTokenProvider: ChainedTokenCredential authentication failed | No Entra ID credential was found. Run az login (or configure a managed identity), or set ANTHROPIC_FOUNDRY_API_KEY. |
| Repeated connection errors on the first prompt | ANTHROPIC_FOUNDRY_RESOURCE is probably a placeholder or a typo, so the endpoint URL built from it does not exist. Use the real resource name. |
| Model or deployment errors | Check the pinned variables match deployment names exactly; Foundry will not fall back. |